İçeriğe atla
Noroxi

exponent kayıtları

exponent üreticisine ait 16 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
4
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Yıllara göre kayıt

    Çubuk: toplam · koyu kısım: CISA KEV.

    Tekrar eden sınıflar

    Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.

    CWE

    Tüm kayıtlar

    16 kayıt
    • CVE-2006-1604
      41Planlayın

      Unspecified vulnerability in Exponent CMS before 0.96.5 RC 1 has unknown impact and remote attack vectors related to variables that are not

      KritikCVSS 10,0İstismar yokEPSS %2

      exponent · exponent cms4 Nis 2006

    • CVE-2005-3764
      40Planlayın

      The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files

      KritikCVSS 10,0İstismar yokEPSS %1

      exponent · exponent22 Kas 2005

    • CVE-2006-1605
      31İzleyin

      Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows remote attackers to execute arbitrary code via unkno

      YüksekCVSS 7,5İstismar yokEPSS %3

      exponent · exponent cms4 Nis 2006

    • CVE-2005-3765
      31İzleyin

      Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to

      YüksekCVSS 7,5İstismar yokEPSS %3

      exponent · exponent22 Kas 2005

    • CVE-2005-3762
      30İzleyin

      SQL injection vulnerability in the navigation module (navigationmodule) in Exponent CMS 0.96.3 and later versions allows remote attackers to

      YüksekCVSS 7,5İstismar yokEPSS %1

      exponent · exponent22 Kas 2005

    • CVE-2006-1607
      30İzleyin

      Unspecified vulnerability in the banner module in Exponent CMS before 0.96.5 RC 1 allows "php injection" via unknown attack vectors.

      YüksekCVSS 7,5İstismar yokEPSS %1

      exponent · exponent cms4 Nis 2006

    • CVE-2006-4963
      27İzleyin

      Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via

      OrtaCVSS 6,4Kavram kanıtıEPSS %7

      exponent · exponent cms23 Eyl 2006

    • CVE-2007-2252
      21İzleyin

      Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive inf

      OrtaCVSS 5,0Kavram kanıtıEPSS %3

      exponent · exponent cms25 Nis 2007

    • CVE-2005-0310
      21İzleyin

      Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.info

      OrtaCVSS 5,0İstismar yokEPSS %2

      exponent · exponent2 May 2005

    • CVE-2005-3763
      20İzleyin

      Exponent CMS 0.96.3 and later versions includes the full installation path in the base parameter to thumb.php, which allows remote attackers

      OrtaCVSS 5,0İstismar yokEPSS %1

      exponent · exponent22 Kas 2005

    • CVE-2005-3767
      20İzleyin

      Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attackers to upload and e

      OrtaCVSS 5,0İstismar yokEPSS %1

      exponent · exponent22 Kas 2005

    • CVE-2007-2253
      20İzleyin

      Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrol

      OrtaCVSS 5,0İstismar yokEPSS %1

      exponent · exponent cms25 Nis 2007

    • CVE-2006-1606
      20İzleyin

      Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows "directory disclosure" with unknown attack vectors.

      OrtaCVSS 5,0İstismar yokEPSS %1

      exponent · exponent cms4 Nis 2006

    • CVE-2005-3766
      20İzleyin

      Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though

      OrtaCVSS 5,0İstismar yokEPSS %1

      exponent · exponent22 Kas 2005

    • CVE-2005-0309
      17İzleyin

      Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitr

      OrtaCVSS 4,3İstismar yokEPSS %1

      exponent · exponent25 Oca 2005

    • CVE-2005-3761
      17İzleyin

      Cross-site scripting (XSS) vulnerability in Exponent CMS 0.96.3 and later versions allows remote attackers to inject arbitrary web script or

      OrtaCVSS 4,3İstismar yokEPSS %1

      exponent · exponent22 Kas 2005